OpenShift AI 3.4.4 security update reaches from the Operator to serving and workbench images
The Critical-rated release touches 106 image families and 143 CVEs; operators need the platform update, not only the earlier AI Inference image replacements.
Red Hat has issued a Critical-rated OpenShift AI 3.4.4 security update that reaches far beyond a single model-server image. RHSA-2026:60520 lists updated platform images, while Red Hat’s machine-readable CSAF advisory identifies 143 vulnerabilities and 106 distinct image families across the release.
What is in the update
The image list spans the OpenShift AI control plane and operator assets, including the Operator bundle, Operator controller, dashboard, CLI and must-gather image. It also reaches the platform’s model-serving layer: KServe controllers and router, llm-d scheduling and routing components, Models-as-a-Service controllers, Llama Stack, the model-serving API and vLLM CPU runtime all appear in the advisory.
The same update refreshes workbench and pipeline runtimes, notebook controllers, MLflow, Feast, KubeRay, Spark and distributed-training images. Trust and safety components are represented too, including TrustyAI services, guardrail detectors and the guardrails orchestrator. The practical point is that the 143-CVE count is spread across a broad platform bill of materials; it does not describe 143 flaws in one OpenShift AI service.
The Operator upgrade path
Red Hat’s remediation text tells customers to move their clusters to OpenShift AI 3.4.4, but it also says the linked product documentation “will be updated shortly” with release-specific instructions. That is an important limitation in the public guidance at publication time: the advisory provides the fixed image set, but not a bespoke 3.4.4 runbook.
The current OpenShift AI 3.4 update-channel documentation says the installed Operator’s Subscription selects the channel used to track and receive Operator updates. Administrators should therefore verify that the Subscription is following the intended supported 3.4 channel, complete whatever approval step their Operator policy requires, and confirm that the Operator and its managed components have reconciled to the 3.4.4 images. Image-level verification matters because the erratum covers both operator-managed services and workload-facing runtimes.
Why this is not the earlier Inference 3.4.4 refresh
Red Hat separately published Important-rated 3.4.4 advisories for Red Hat AI Inference images on August 20. The CPU advisory covers one CPU serving image and five CVEs; separate advisories map the CUDA and Spyre variants to their replacement images.
RHSA-2026:60520 is the OpenShift AI platform update. Replacing a standalone AI Inference image does not update the OpenShift AI Operator, dashboard, KServe and llm-d control components, pipelines, workbenches or TrustyAI images listed in the newer advisory. Clusters running OpenShift AI 3.4 need the platform’s 3.4.4 update path even if their model-serving image was already refreshed under the earlier Inference advisories.
sources
- RHSA-2026:60520 — Red Hat OpenShift AI 3.4.4access.redhat.com
- Red Hat CSAF data for RHSA-2026:60520security.access.redhat.com
- OpenShift AI 3.4 — Understanding update channelsdocs.redhat.com
- RHSA-2026:57380 — Red Hat AI Inference 3.4.4 CPU imageaccess.redhat.com
- RHSA-2026:57389 — Red Hat AI Inference 3.4.4 CUDA imageaccess.redhat.com
- RHSA-2026:57387 — Red Hat AI Inference 3.4.4 Spyre imageaccess.redhat.com
comments · 0